@mintlify/validation
Validates mint.json files
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions CI is a documented legitimate pattern for this established Mintlify package. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): js-yaml is explicitly declared as a direct dependency in package.json; the phantom-dep finding is a false positive for this package. | ai | |
| dependencies | unvetted-dep:lcm | AI (dependencies): lcm is a small math utility pinned at 0.0.3 with @types/lcm in devDeps; intentional, typed usage with no malware signals. | ai | |
| typosquat | typosquat.levenshtein:validator | AI (typosquat): Scoped @mintlify/validation package is clearly named for its purpose (validating mint.json files), not impersonating the 'validator' package. False positive for this namespace. | ai | |
| dependencies | unvetted-dep:@mintlify/mdx | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai | |
| dependencies | unvetted-dep:@mintlify/models | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai |
Versions (showing 51 of 359)
| Version | Deps | Published |
|---|---|---|
| 0.1.715 | 12 / 14 | |
| 0.1.714 | 12 / 14 | |
| 0.1.713 | 12 / 14 | |
| 0.1.712 | 12 / 14 | |
| 0.1.711 | 12 / 14 | |
| 0.1.710 | 12 / 14 | |
| 0.1.709 | 12 / 16 | |
| 0.1.708 | 12 / 16 | |
| 0.1.707 | 12 / 16 | |
| 0.1.706 | 12 / 16 | |
| 0.1.705 | 12 / 16 | |
| 0.1.704 | 12 / 16 | |
| 0.1.703 | 12 / 16 | |
| 0.1.702 | 12 / 16 | |
| 0.1.701 | 12 / 16 | |
| 0.1.700 | 12 / 16 | |
| 0.1.699 | 12 / 16 | |
| 0.1.698 | 12 / 16 | |
| 0.1.697 | 12 / 16 | |
| 0.1.696 | 12 / 16 | |
| 0.1.695 | 12 / 16 | |
| 0.1.694 | 12 / 16 | |
| 0.1.693 | 12 / 16 | |
| 0.1.692 | 12 / 16 | |
| 0.1.691 | 12 / 16 | |
| 0.1.690 | 12 / 16 | |
| 0.1.689 | 12 / 16 | |
| 0.1.688 | 12 / 16 | |
| 0.1.687 | 12 / 16 | |
| 0.1.686 | 12 / 16 | |
| 0.1.685 | 12 / 16 | |
| 0.1.684 | 12 / 16 | |
| 0.1.683 | 12 / 16 | |
| 0.1.682 | 12 / 16 | |
| 0.1.681 | 12 / 16 | |
| 0.1.680 | 12 / 16 | |
| 0.1.679 | 12 / 16 | |
| 0.1.678 | 12 / 16 | |
| 0.1.677 | 12 / 16 | |
| 0.1.676 | 12 / 16 | |
| 0.1.675 | 12 / 16 | |
| 0.1.674 | 12 / 16 | |
| 0.1.673 | 12 / 16 | |
| 0.1.672 | 12 / 16 | |
| 0.1.671 | 12 / 16 | |
| 0.1.670 | 12 / 16 | |
| 0.1.669 | 12 / 16 | |
| 0.1.668 | 12 / 16 | |
| 0.1.667 | 12 / 16 | |
| 0.1.666 | 12 / 16 | |
| 0.1.665 | 12 / 16 |
v0.1.715
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.714
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.713
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.712
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.711
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.710
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.709
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.708
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.707
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.706
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.705
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.704
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.703
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.702
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.701
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.700
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.699
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.698
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.697
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.696
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.695
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.694
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.693
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.692
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.691
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.690
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.689
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.688
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.687
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.686
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.685
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.684
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.683
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.682
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.681
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.680
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.679
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.678
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.677
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.676
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.675
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.674
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.673
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.672
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.671
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.670
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.669
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.668
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.667
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.666
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.665
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.